VulnerabilityAnalyzed
CVE-2026-4936
An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.
MEDIUM 6.2EPSS 0.07%
Does this matter?
Lower severity and a low EPSS score (0.07%). Track it; it rarely justifies an emergency change on its own.
Description
IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.
- CVSS 3.1
- 6.2 MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.07% probability · 0th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-331
- Affected
- ibm/power system s1122 \(9824-22a\) firmware · ibm/power system s1124 \(9824-42a\) firmware · ibm/power system s1122s \(9824-22b\) firmware · ibm/power system s1114 \(9824-41b\) firmware · ibm/power system l1122 \(9856-22h\) firmware · ibm/power system l1124 \(9856-42h\) firmware · ibm/power system e1150 \(9043-mru\) firmware · ibm/power system s1112 \(9242-21b\) firmware · ibm/power system s1112 \(9242-21t\) firmware · ibm/power system e1080 \(9080-hex\) firmware · ibm/power system s1022 \(9105-22a\) firmware · ibm/power system s1024 \(9105-42a\) firmware · ibm/power system s1022s \(9105-22b\) firmware · ibm/power system s1014 \(9105-41b\) firmware · ibm/power system l1022 \(9786-22h\) firmware · ibm/power system l1024 \(9786-42h\) firmware · ibm/power system e1050 \(9043-mrx\) firmware · ibm/power system s1012 \(9028-21b\) firmware · ibm/power system e1180 \(9080-heu\) firmware · ibm/power system s922 \(9009-22g\) firmware · +6 more
- Source
- psirt@us.ibm.com
References
- https://www.ibm.com/support/pages/node/7283890Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.